PT-2026-60293 · Zoom · Zoom Workplace+1
CVE-2026-53412
·
Published
2026-07-14
·
Updated
2026-08-12
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Zoom Workplace for Windows versions prior to 7.0.0
Zoom VDI Client for Windows versions prior to 7.0.10
Zoom VDI Client for Windows versions prior to 6.6.15
Zoom VDI Client for Windows versions prior to 6.5.18
Zoom Meeting SDK for Windows versions prior to 7.0.0
Description
An improper input validation issue exists in the Windows desktop client, VDI client, and Meeting SDK. This flaw allows an unauthenticated remote attacker with network access to perform a full account takeover without requiring user credentials or interaction. Improper input validation occurs when a software application fails to properly verify or filter the data it receives, which can lead to unexpected behavior or security breaches.
Recommendations
Update Zoom Workplace for Windows to version 7.0.0 or later.
Update Zoom VDI Client for Windows to versions 7.0.10, 6.6.15, or 6.5.18 depending on the specific branch.
Update Zoom Meeting SDK for Windows to version 7.0.0 or later.
Enforce multi-factor authentication (MFA), single sign-on (SSO), and conditional access.
Restrict local administrator rights to reduce the impact of potential privilege escalation.
Monitor for suspicious account activity and unusual login patterns.
Fix
LPE
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoom Workplace
Zoom